ffl. AMENDMENTS TO THE CLAIMS: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application. 

Listing of Claims: 

Claims 1-212 (canceled) 

213. (New): Method for creating and managing multilateral contractual 
relationships among contracting parties under a privacy standard, said contracting parties 
comprising (1) "covered entities" receiving data of customers and creating, recording, 
using, and disclosing private data of such customers in the ordinary course of business, 
and (2) "business associates" requiring the use of said private data, said method 
comprising the steps of: 

(a) assigning digital identities to the contracting parties; 

(b) providing a multilateral Master Business Associate Contract (MBAC) template 
having non-negotiable terms requiring observation of said privacy standard with respect to 
said private data of a customer; 

(c) providing an electronic interface accessible to said digital identities to facilitate 
negotiating and entering binding multilateral contractual agreements among at least one of 
said covered entities and a plurality of said business associates pursuant to the terms of 
said MBAC template; and 

(d) storing said multilateral contractual agreements in an MBAC database. 

214. (New): The method according to claim 213, including the additional step of 
providing self-certification provisions in said MBAC for contracting parties to certify 
adherence to said privacy standard as self-certified covered entities or as self-certified 
business associates. 

215. (New): The method according to claim 213, wherein said electronic 
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interface includes interactive means for negotiating additional terms with respect to use or 
disclosure of said private data. 

216. (New): Method for creating and managing multilateral contractual 
relationships among contracting parties under a privacy standard, said contracting parties 
comprising (1) "covered entities" receiving data of customers and creating, recording, 
using, and disclosing private data of such customers in the ordinary course of business, 
and (2) "business associates" requiring the use of said private data, said method 
comprising the steps of: 

(a) assigning digital identities to the contracting parties; 

(b) providing a multilateral Master Business Associate Contract (MBAC) template 
having non-negotiable terms requiring observation of said privacy standard with respect to 
said private data of a customer; 

(c) providing self-certification procedures for contracting parties to certify 
adherence to said privacy standard as self-certified covered entities or as self-certified 
business associates; 

(d) providing an electronic interface accessible to said digital identities to facilitate 
negotiating and entering binding multilateral contractual agreements among at least one of 
said self-certified covered entities and a plurality of said self-certified business associates 
pursuant to the terms of said MBAC template; and (e) storing said multilateral contractual 
agreements in an MBAC database. 

217. (New): The method according to claim 216, wherein said self-certification 
procedures comprise the additional steps of: providing a self-certification standard 
affidavit template for self-certification by electronic signature; and storing affidavits 
corresponding to said template in a separate self-certification database. 

218. (New): The method according to claim 216, wherein said self-certification 
procedures comprise warranty clauses in said MBAC. 

219. (New): The method according to claim 216, wherein said electronic 
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interface includes interactive means for negotiating said additional terms with respect to 
use or disclosure of said private data. 

220. (New): The method according to claim 216, wherein said interactive means 
includes means for a covered entity to offer and for a business associate to accept said 
non-negotiable terms in the MBAC. 

221 . (New): The method according to claim 216 including the additional step of: 
accessing a selected multilateral contractual agreement in said MBAC database for 
permission to disclose selected private data to a selected self-certified business associate. 

222. (New): The method according to claim 216, wherein said electronic 
interface comprises the internet. 

223. (New): Method for creating and managing multilateral contractual 
relationships among contracting parties under a privacy standard applicable to protected 
health information (PHI), said contracting parties comprising (1) "covered entities" 
receiving data of customers and creating, recording, using, and disclosing PHI data of such 
customers in the ordinary course of business, and (2) "business associates" requiring the 
use of said PHI data, said method comprising the steps of: 

(a) assigning digital identities to the contracting parties; 

(b) providing a multilateral Master Business Associate Contract (MBAC) template 
having non-negotiable terms requiring observation of said privacy standard with respect to 
said PHI data of a customer; 

(c) providing a self-certification standard affidavit template for contracting parties 
to certify adherence to said privacy standard as self-certified covered entities or as self- 
certified business associates by electronic signature so as to achieve self-certification; 

(d) storing affidavits corresponding to said template in a separate self-certification 
database; 

(e) providing an electronic interface accessible to said digital identities, said 
electronic interface being selectively connectable to the self-certification database to 
facilitate negotiating and entering binding multilateral contractual agreements among at 
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least one of said self-certified covered entities and a plurality of said self-certified business 
associates pursuant to the terms of said affidavits and said MBAC template; and 
(f) storing said multilateral contractual agreements in an MBAC database. 

224. (New): The method according to claim 223, wherein said electronic 

interface includes interactive means for negotiating said additional terms with respect to 
use or disclosure of said PHI data. 

4 225. (New): The method according to claim 223, wherein said interactive means 

includes means for a covered entity to offer and for a business associate to accept said 
non-negotiable terms in the MBAC. 

226. (New): The method according to claim 223 including the additional step of: 
accessing a selected multilateral contractual agreement in said MBAC* database for 
permission to disclose selected PHI data to a selected self-certified business associate. 

227. (New): The method according to claim 223, wherein said electronic 
interface comprises the internet. 

228. (New): Method for creating and managing contractual relationships among 
interacting parties under a privacy standard, said interacting parties comprising (1) 
"covered entities" and (2) "business associates" between which private information is 
exchanged, said method comprising the steps of: 

issuing digital certificates to the interacting parties; 

providing community rules having a minimum standard based on said privacy 
standard requiring compliance of said privacy standard with respect to said private 
information; 

providing an electronic interface accessible to said interacting parties to facilitate 
negotiating and entering binding agreements among at least one of said covered entities 
and a plurality of said business associates pursuant to the terms of said community rules; 
and 

storing said binding agreements in a database. 
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229. (New): The method according to claim 228, further comprising the step of 
providing certificates of compliance certifying that said interacting parties comply with 
said community rules. 

230. (New): The method according to claim 228, wherein said electronic 
interface facilitates negotiating additional requirements with respect to use or disclosure of 
said private information. 

231. (New): Method for creating and managing contractual relationships among 
interacting parties under a privacy standard, said interacting parties comprising (1) 
"covered entities" and (2) "business associates" between which private information is 
exchanged, said method comprising the steps of: 

issuing digital certificates to the interacting parties; 

providing community rules having a minimum standard based on said privacy 
standard requiring compliance of said privacy standard with respect to said private 
information; 

providing certificates of compliance certifying that said interacting parties comply 
with said community rules; 

providing an electronic interface accessible to said interacting parties to facilitate 
negotiating and entering binding agreements among at least one of said covered entities 
and a plurality of said business associates pursuant to the terms of said community rules; 
and 

storing said binding agreements in a database. 

232. (New): The method according to claim 231, wherein said step of providing 
certificates of compliance comprises the steps of: 

validating said certificate of compliance; and 
storing said certificate of compliance in said database. 

233. (New): The method according to claim 231, wherein said electronic 
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interface facilitates negotiating additional requirements with respect to use or disclosure of 
said private information. 

234. (New): The method according to claim 231, wherein said electronic 
interface facilitates a covered entity to offer and a business associate to accept said 
community rules having said minimum standard. 

235. (New): The method according to claim 231 further comprising the step of 
querying a target member for permission to disclose selected private information to said 
target member. 

236. (New): The method according to claim 231, wherein said electronic 
interface comprises the internet. 

237. (New): Method for creating and managing contractual relationships among 
interacting parties under a privacy standard applicable to protected health information 
(PHI), said interacting parties comprising (1) "covered entities" and (2) "business 
associates" between which private information is exchanged, said method comprising the 
steps of: 

issuing digital certificates to the interacting parties; 

providing community rules having a minimum standard based on said privacy 
standard requiring compliance of said privacy standard with respect to said PHI; 

providing an electronic interface accessible to said interacting parties to facilitate 
negotiating and entering binding agreements among at least one of said covered entities 
and a plurality of said business associates pursuant to the terms of said community rules; 

providing an agreement for said interacting parties to certify adherence to said 
privacy standard by electronic signature; and 

storing said agreement in a database. 

238. (New): The method according to claim 237, wherein said electronic 
interface facilitates negotiating additional requirements with respect to use or disclosure of 
said PHI. 
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239. (New): The method according to claim 237, wherein said electronic 
interface facilitates a covered entity to offer and a business associate to accept said 
community rules having said minimum standard. 

240. (New): The method according to claim 237, further comprising the step of 
querying a target member for permission to disclose selected PHI to said target member. 

241. (New): The method according to claim 237, wherein said electronic 
interface comprises the internet. 
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